Last month, I spent about a week working on Plasma Bigscreen, hoping to get it back in Plasma releases again!
Read about it on my blog: espi.dev/posts/2025/07/plasma-…
#kde
Diving into Plasma Bigscreen | espidev
I have been a long time Plasma Mobile contributor, but I have always had a keen interest in having Linux on my TV! I have noticed that in the past few months, the Plasma Bigscreen project has had some interest from people wanting to contribute, but t…espi.dev
reshared this


otto@openbsd
Unknown parent • • •abadidea
Unknown parent • • •Dr. Christopher Kunz
Unknown parent • • •daniel:// stenberg://
Unknown parent • • •M Schommer
Unknown parent • • •@skyr
Yes, there's a ton of exceptions from CRA regulations for FLOSS projects. But they don't excempt commercial companies from their CRA duties when incorporating FLOSS in their products. See Recital 34.
@bagder
Shred
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to Shred • • •Fubaroque
Unknown parent • • •daniel:// stenberg://
in reply to Fubaroque • • •M Schommer
in reply to daniel:// stenberg:// • • •I would love to see that questionary (with or without senders' company name) and your answers.
You could have the opportunity here to start some kind of best practice for FLOSS projects with publishing all such questionaries+answers in some /cra directory on the curl website.
Maybe that's also an option for your support contract pricing model:
Support contract with right to publish questionary+answers… normal price
Contract with questionary+answers hidden… double price?
Fubaroque
in reply to daniel:// stenberg:// • • •They don’t seem to have that option (to stop using curl) is what I mean. After all curl is everywhere…
Which makes their negotiating position rather weak. And any “deadlines” their problem. Have fun!
M Schommer
Unknown parent • • •Yes, you're right. I didn't remember correctly.
@otto
VessOnSecurity
in reply to daniel:// stenberg:// • • •Tim Ward ⭐🇪🇺🔶 #FBPE
Unknown parent • • •Newk
in reply to daniel:// stenberg:// • • •robertmx
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to daniel:// stenberg:// • • •Duncan Bayne
in reply to daniel:// stenberg:// • • •Klaus Vink Slott
in reply to daniel:// stenberg:// • • •Jia Tan's mom
in reply to daniel:// stenberg:// • • •Poul-Henning Kamp
in reply to daniel:// stenberg:// • • •Not quite the questions I got, but similar outline.
BTW: It is not obvious to me what the legal status of our answers will be, and what liability we might pick up with them.
That's why I quoted T&M: I would want to talk to a lawyer before answering.
Mitsunee | 光音
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to Mitsunee | 光音 • • •blami
in reply to daniel:// stenberg:// • • •blami
in reply to blami • • •daniel:// stenberg://
in reply to blami • • •blami
in reply to daniel:// stenberg:// • • •Troed Sångberg
in reply to daniel:// stenberg:// • • •Have you been able to sign any new contracts originating from CRA so far?
@blami @mitsunee
Lars Eggert
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to Lars Eggert • • •MaineC
in reply to daniel:// stenberg:// • • •Rafa Font 🌻 🇪🇺 🏀
in reply to daniel:// stenberg:// • • •Matt Lacey
in reply to daniel:// stenberg:// • • •Matt Lacey
in reply to daniel:// stenberg:// • • •Moritz Dietz
in reply to daniel:// stenberg:// • • •Milly
in reply to daniel:// stenberg:// • • •Fubaroque
in reply to daniel:// stenberg:// • • •Regulation - 2024/2847 - EN - EUR-Lex
eur-lex.europa.euijk64✅
in reply to daniel:// stenberg:// • • •Jernej Virag
in reply to daniel:// stenberg:// • • •Wouter
in reply to daniel:// stenberg:// • • •A6: "Yes. We don't know. The vulnerabilities haven't been discovered yet."
(or do they mean "known vulnerabilities"? 😜)
Joakim Melin
in reply to daniel:// stenberg:// • • •1m_0
in reply to daniel:// stenberg:// • • •Anton Klinger
in reply to daniel:// stenberg:// • • •embix
in reply to daniel:// stenberg:// • • •divVerent
in reply to daniel:// stenberg:// • • •Based on github.blog/open-source/mainta… you are at most a "steward" under the CRA and would have rather minimal requirement. This questionnaire definitely goes beyond that.
Having said that, the questions are extremely weaseley. "Is appropriate cybersecurity testing in place" can easily be answered with yes if no testing is mandated for you as a steward, but it sure is not what the asker expects...
What the EU’s new software legislation means for developers - The GitHub Blog
Felix Reda (The GitHub Blog)daniel:// stenberg://
in reply to divVerent • • •TobiX
in reply to daniel:// stenberg:// • • •Stefan Scholl
in reply to daniel:// stenberg:// • • •radentscheiderin :ferris:
in reply to daniel:// stenberg:// • • •Alan Hicks
in reply to daniel:// stenberg:// • • •Nikolai Hampton 💾
in reply to daniel:// stenberg:// • • •Dear ,
I haven’t the motivation to answer your questions so I’ve had my LLM complie these responses for your records. Should you require a considered, articulate, Human response, then contact me to make commercial arrangements. U til then, I hope the following is sufficient:
Absolutely. We follow the Secure Software Development Lifecycle of the Ancient Order of the
Keyboard Knights, wherein bugs are ritually exorcised by moonlight. Our threat model includes gremlins, entropy, and the eventual heat death of the universe.
2. Do you provide regular security updates for “libcurl”?
Yes, on every second Tuesday that coincides with a solar flare. Security updates are broadcast via carrier pigeon to subscribers of our psychic mailing list. You’re on that, right?
3. Is there any discontinuation/End of life for the latest version of “libcurl” in near future?
Yes. Support will cease five minutes after you read this sentence. Any continued use past that is on you, your shareholders, and possibly your descendants.
4. Do you have Long Term support for “libcurl”?
Yes. LTS extends until the next time someone rage-quits after reading corporate compliance forms. Estimated duration: ∞ ± a nervous breakdown.
5. Is appropriate cybersecurity testing followed? If yes, is any specific standard for testing used?
We use the highly regarded YOLO/420 framework, which relies on vibes, sarcasm, and staring very hard at the code until it either confesses or crashes.
6. Are there any vulnerabilities in the latest version which are not disclosed publicly?
We don’t disclose them publicly. We disclose them secretly during developer sleep cycles. If you’re not picking them up, maybe update your firmware.
7. Is the vulnerability handling procedure available for “libcurl”?
Yes. It involves screaming into a GitHub issue tracker and then sacrificing a merge request under a new moon. Full documentation is encrypted into the Fibonacci sequence.
8. Do you comply with EU-CRA requirements?
We comply with a CRA—the Cosmic Randomness Accord—which governs the behavior of open-source electrons. The EU one, nobody knows but it sounds tedious.
9. Do you provide proof of conformity regarding adherence to EU-CRA?
Yes, we have a 1:1 scale interpretive dance reenactment available on VHS. Please provide your own tape and CRT for viewing and legal review.
⸻
Let me know if you want versions that walk the line closer to plausible deniability or should be translated into bureaucratic doublespeak.
Simon Brooke
in reply to daniel:// stenberg:// • • •soc
in reply to daniel:// stenberg:// • • •"libcurl" ... jeez.
I hope you quoted the company's name in your reply to sound equally dismissive.
RevK
in reply to daniel:// stenberg:// • • •I'd be "read LICENCE file" for all answers.
I'm happy to answer in more detail for £100/hour, but the answers may turn out to be the same.
But in seriousness, it is more...
"No, this is free software, but as such you can fork it, take it on in to your own s/w dev team, and have them answer all those questions if you need for this."
Lorenzo 'kelset' Sciandra
in reply to daniel:// stenberg:// • • •Martin Boller
in reply to daniel:// stenberg:// • • •dgelessus
in reply to daniel:// stenberg:// • • •🇺🇦 Anna Filina
in reply to daniel:// stenberg:// • • •🇺🇦 Anna Filina
in reply to daniel:// stenberg:// • • •�
in reply to daniel:// stenberg:// • • •primalmotion
in reply to daniel:// stenberg:// • • •incredible. these fucks not only require you to work for free, but they put a deadline. Like it's a privilege they decided to use curl.
your reply has been more polite than what I could ever have replied.
Yet another Josh
in reply to daniel:// stenberg:// • • •ANSWER: The answer to this question will cost 100000 Euro to answer.
ANSWER: The answer to this question will cost 100000 Euro to answer.
ANSWER: The answer to this question will cost 100000 Euro to answer.
ANSWER: The answer to this question will cost 100000 Euro to answer.
ANSWER: The answer to this question will cost 100000 Euro to answer.
ANSWER: The answer to this question will cost 100000 Euro to answer.
ANSWER: The answer to this question will cost 100000 Euro to answer.
ANSWER: The answer to this question will cost 100000 Euro to answer.
ANSWER: The answer to this question will cost 100000 Euro to answer.
NOTE: Paying for 1 question does not guarantee answering other questions. Payment is due upon request in full.
😂
gabriele renzi
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to gabriele renzi • • •Brokar
in reply to daniel:// stenberg:// • • •Well, you could answer
"Depends on what you pay me on a monthly basis for my support towards your company, fulfilling all you cyber needs regarding libcurl. Read the license agreement. Please find all further information on our website."
And if they use your software within their products, then they should already know all the answers if they had done their job right.
SMillerNL
in reply to daniel:// stenberg:// • • •LiquorVicar
in reply to daniel:// stenberg:// • • •Andy Piper
in reply to daniel:// stenberg:// • • •Winni Neessen
in reply to daniel:// stenberg:// • • •Andreas Scherbaum
in reply to daniel:// stenberg:// • • •Richard Bairwell
in reply to daniel:// stenberg:// • • •"As these questions can only be answered during an annual support contract, I would advise that in the interim that your usage of libcurl is halted immediately as these security questions cannot be responded to"
I wonder how much panic there would be in their dev team ...
Ben Hammond
in reply to daniel:// stenberg:// • • •Speed demon 🇪🇺 🇳🇴🇺🇦🇵🇸
in reply to daniel:// stenberg:// • • •Uwe Trenkner
Unknown parent • • •Dan
Unknown parent • • •prom™️
Unknown parent • • •Joykill
in reply to daniel:// stenberg:// • • •Stumpy The Mutt
in reply to daniel:// stenberg:// • • •soc
Unknown parent • • •Thomas Svensson 🖖
Unknown parent • • •Reading through your posts about CRA, I think there is a chance for a CRUde awakening for these companies.
A reality check even, about how open source actually works. Including having to read the licenses and realizing they use it, for free, on their own risk.
Leaving the eat the risk, get a support contract or stop using.
So after the initial drama, this could be a good thing for open source in the long run.
Krupo
in reply to daniel:// stenberg:// • • •how dare the EU co-opt the Canada Revenue Agency
I will forever assume any CRA reference has to do with our taxes :)
Paul Wunderlich
in reply to daniel:// stenberg:// • • •Anton Piatek
Unknown parent • • •sayitintexan
in reply to daniel:// stenberg:// • • •Osma A 🇫🇮🇺🇦
in reply to daniel:// stenberg:// • • •@bagder
Ryan Finnie
Unknown parent • • •fuzzyfuzzyfungus
in reply to daniel:// stenberg:// • • •chfkch
Unknown parent • • •The Penguin of Evil
in reply to daniel:// stenberg:// • • •Felix Reda
in reply to daniel:// stenberg:// • • •Fazal Majid
in reply to daniel:// stenberg:// • • •Momo
in reply to daniel:// stenberg:// • • •v7.87.0, released on 21.12.2022.
...do you think those people feel anything at this point?
daniel:// stenberg://
Unknown parent • • •Jan Penfrat
in reply to daniel:// stenberg:// • • •Oh wow! Could you tell them you're happy to answer their questions in return for a 100k donation?
(NB: We warned EU lawmakers when they drafted the #CRA that this might happen but they were mostly doing 🙈🙉🙊)
Ian Jackson
in reply to daniel:// stenberg:// • • •I am typically much much ruder to them than @simontatham or the actual PuTTY team are
daniel:// stenberg://
Unknown parent • • •Account: Computers
Unknown parent • • •Ronan Klyne
in reply to daniel:// stenberg:// • • •"THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED..."
It's not even fine print.
Might be worth copying the license to a CRA statement in the codebase?
ch2500
in reply to daniel:// stenberg:// • • •JCWasmx86
Unknown parent • • •